Vulnerability index

Browse CVEs

5,504 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Unclassified MEDIUM 6.5
CVE-2026-13329

The Buckaroo Woocommerce Payments Plugin WordPress plugin before 4.9.0 does not perform any capability check or nonce validation on an AJAX action th…

No fix yet
Fix from $1,600 2026-08-01
Unclassified MEDIUM 5.3
CVE-2026-12966

The Direct Payments for WooCommerce WordPress plugin before 2.5.3 does not verify that the requester owns the targeted WooCommerce order in several …

No fix yet
Fix from $1,600 2026-08-01
Unclassified MEDIUM 6.5
CVE-2026-45377

Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the normal download_…

No fix yet
Fix from $1,600 2026-07-31
Unclassified CRITICAL 9.8
CVE-2026-52134

An issue in the parseGoosePayload() function (/goose/goose_receiver.c) of libiec61850 v1.6 allows attackers to bypass authentication via a captured G…

No fix yet
Fix from $2,300 2026-07-31
Unclassified MEDIUM 5.3
CVE-2026-65311

The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions exposes an undocumented endpoint that changes the server's …

No fix yet
Fix from $1,600 2026-07-31
Unclassified MEDIUM 6.5
CVE-2026-14834

The Mailgun for WordPress plugin before 2.2.1 does not perform any capability or nonce check on an unauthenticated AJAX action that adds subscribers …

No fix yet
Fix from $1,600 2026-07-31
Unclassified HIGH 8.5
CVE-2026-62246

Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, Kamaji derives a TenantControlPlane datastore schema, database user,…

No fix yet
Fix from $1,950 2026-07-30
Azure Cosmos Db CRITICAL 10.0
CVE-2026-66803

Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.

No fix yet
Fix from $2,300 2026-07-30
Unclassified HIGH 7.5
CVE-2026-58043

A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`, an atta…

No fix yet
Fix from $1,950 2026-07-30
Unclassified HIGH 7.3
CVE-2026-16527

An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacke…

No fix yet
Fix from $1,950 2026-07-30
Unclassified MEDIUM 5.3
CVE-2026-15250

The Appointment Booking Plugin WordPress plugin before 5.6.8 does not restrict which booking fields an unauthenticated visitor can set through its p…

No fix yet
Fix from $1,600 2026-07-30
Unclassified MEDIUM 5.9
CVE-2026-11782

The Points and Rewards for WooCommerce WordPress plugin before 2.10.1 does not have authorisation checks in place on a wallet and points update actio…

No fix yet
Fix from $1,600 2026-07-30
Chrome MEDIUM 6.2
CVE-2026-17996

Inappropriate implementation in Browser in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to bypass navigation restrictions via…

Fix: 151.0.7922.72+
Fix from $1,600 2026-07-30
Chrome MEDIUM 6.5
CVE-2026-17986

Insufficient policy enforcement in Bluetooth in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer proce…

Fix: 151.0.7922.72+
Fix from $1,600 2026-07-30
Chrome MEDIUM 6.5
CVE-2026-17917

Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass discretionary ac…

Fix: 151.0.7922.72+
Fix from $1,600 2026-07-30
Chrome MEDIUM 6.5
CVE-2026-17873

Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass discretionary ac…

Fix: 151.0.7922.72+
Fix from $1,600 2026-07-30
Chrome MEDIUM 6.5
CVE-2026-17825

Insufficient policy enforcement in Passwords in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to bypass discretionary acc…

Fix: 151.0.7922.72+
Fix from $1,600 2026-07-30
Chrome MEDIUM 6.5
CVE-2026-17830

Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrict…

Fix: 151.0.7922.72+
Fix from $1,600 2026-07-30
Chrome MEDIUM 6.5
CVE-2026-17824

Insufficient policy enforcement in ServiceWorker in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a…

Fix: 151.0.7922.72+
Fix from $1,600 2026-07-30
Chrome MEDIUM 6.3
CVE-2026-17780

Inappropriate implementation in Isolated Web Apps in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions…

Fix: 151.0.7922.72+
Fix from $1,600 2026-07-30
Unclassified HIGH 8.3
CVE-2026-67431

MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StreamableHTTPTranspo…

No fix yet
Fix from $1,950 2026-07-29
Gridbox CRITICAL 9.8
CVE-2026-65887

Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allows actors to reset any u…

Fix: 2.20.2+
Fix from $2,300 2026-07-29
Gridbox CRITICAL 9.8
CVE-2026-65888

Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows actors to login as any given user…

Fix: 2.20.2+
Fix from $2,300 2026-07-29
Gridbox HIGH 7.5
CVE-2026-65889

Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion < 2.20.2 - The generateNewApp method allows actors to recursively delet…

Fix: 2.20.2+
Fix from $1,950 2026-07-29
Ro Csvi HIGH 7.5
CVE-2026-65943

Joomla Extension - rolandd.com - Unauthenticated directory creation RO CSVI < 9.11.0

Fix: 9.11.0+
Fix from $1,950 2026-07-29
Gridbox CRITICAL 9.8
CVE-2026-65884

Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing una…

Fix: 2.20.2+
Fix from $2,300 2026-07-29
Traffic Server CRITICAL 9.3
CVE-2026-41920

Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.1.14, from 10.0.0 thr…

Fix: 9.2.15 / 10.1.4+
Fix from $2,300 2026-07-29
Unclassified CRITICAL 9.1
CVE-2026-64863

goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.4, the httpserver/server.go wdGuard handled WebDAV MOV…

Mitigation only
Fix from $2,300 2026-07-28
Sterling B2b Integrator MEDIUM 6.5
CVE-2026-7362

IBM Sterling B2B Integrator 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.1.0 through 6.2.1.1_2, and 6.2…

Fix: after 6.2.2.0_1
Fix from $1,600 2026-07-28
Unclassified HIGH 8.8
CVE-2026-62427

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To manage the syste…

Mitigation only
Fix from $1,950 2026-07-28